---
title: "Poland Confirms Hackers Reached Control Systems… | Firevault"
description: "Poland's Internal Security Agency has confirmed that attackers reached the industrial control systems of five water treatment plants during 2025, in some…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/poland-water-plants-ics-breach-2026#webpage",
      "url": "https://fire-vault.com/news/poland-water-plants-ics-breach-2026",
      "name": "Poland Confirms Hackers Reached Control Systems…",
      "description": "Poland's Internal Security Agency has confirmed that attackers reached the industrial control systems of five water treatment plants during 2025, in some…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/c7e26eeb-fc3c-41ea-9ffe-2a71e5b07ee5/poland-water-plants-ics-breach-2026-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/poland-water-plants-ics-breach-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/poland-water-plants-ics-breach-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Poland Confirms Hackers Reached Control Systems at Five Water Treatment Plants",
          "item": "https://fire-vault.com/news/poland-water-plants-ics-breach-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Poland Confirms Hackers Reached Control Systems at Five Water Treatment Plants",
      "description": "Poland's Internal Security Agency has confirmed that attackers reached the industrial control systems of five water treatment plants during 2025, in some cases gaining the ability to alter equipment settings. The target is no longer data alone, it is physical process control.",
      "url": "https://fire-vault.com/news/poland-water-plants-ics-breach-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/c7e26eeb-fc3c-41ea-9ffe-2a71e5b07ee5/poland-water-plants-ics-breach-2026-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/c7e26eeb-fc3c-41ea-9ffe-2a71e5b07ee5/poland-water-plants-ics-breach-2026-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/c7e26eeb-fc3c-41ea-9ffe-2a71e5b07ee5/poland-water-plants-ics-breach-2026-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/c7e26eeb-fc3c-41ea-9ffe-2a71e5b07ee5/poland-water-plants-ics-breach-2026-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-08-11T06:55:11.608791+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/poland-water-plants-ics-breach-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 675,
      "keywords": "Poland, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Poland's Internal Security Agency (ABW) has confirmed that attackers reached the industrial control systems of five municipal water treatment plants during 2025. In some cases the intruders gained the ability to change equipment settings, which in the worst case could have affected water supply and water safety. The findings were published in the agency's 2024 to 2025 activity report and were repo",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What did Poland's ABW report about water treatment plants?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The Internal Security Agency confirmed that attackers reached the industrial control systems of five water treatment plants during 2025, in Jablonna Lacka, Szczytno, Maldyty, Tolkmicko and Sierakowo. In some cases the intruders gained the ability to alter equipment settings, which could have disrupted water supply."
          }
        },
        {
          "@type": "Question",
          "name": "Why is an attack on operational technology different from a data breach?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Operational technology controls a physical process. A compromised login can map to pumps, valves, chemical dosing, filtration stages and alarms, so the consequence is a plant behaving in a way the operator did not command rather than the loss of records alone."
          }
        },
        {
          "@type": "Question",
          "name": "How does Offline Secure Storage protect an industrial site?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "It holds a gold copy of the engineering and configuration record, including controller programs, set points, baselines and system images, on hardware that is physically disconnected when not in use. An attacker inside the connected estate cannot read, encrypt or delete a copy that is not connected, so restoration starts from a verified reference."
          }
        },
        {
          "@type": "Question",
          "name": "Does this support Cyber Assessment Framework alignment?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. An offline gold copy of the configuration record maps to CAF outcomes for asset and configuration management under Objective A, protection of essential functions under Objective B, and restoration of essential function under Objective D. Firevault maps controls to CAF outcomes rather than claiming certification."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What HappenedWhy This Matters Beyond PolandThe Firevault ViewWhat Operators Should Do NowSourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 11 August 2026 

# Poland Confirms Hackers Reached Control Systems at Five Water Treatment Plants

Poland's Internal Security Agency has confirmed that attackers reached the industrial control systems of five water treatment plants during 2025, in some cases gaining the ability to alter equipment settings. The target is no longer data alone, it is physical process control.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fpoland-water-plants-ics-breach-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fpoland-water-plants-ics-breach-2026&text=Poland%20Confirms%20Hackers%20Reached%20Control%20Systems%20at%20Five%20Water%20Treatment%20Plants%0A%0APoland's%20Internal%20Security%20Agency%20has%20confirmed%20that%20attackers%20reached%20the%20industrial%20control%20systems%20of%20five%20water%20treatment%20plants%20during%202025%2C%20in%20some%20cases%20gaining%20the%20ability%20to%20alter%20equipment%20settings.%20The%20target%20is%20no%20longer%20data%20alone%2C%20it%20is%20physical%20process%20control.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fpoland-water-plants-ics-breach-2026)[](mailto:?subject=Poland%20Confirms%20Hackers%20Reached%20Control%20Systems%20at%20Five%20Water%20Treatment%20Plants&body=Poland's%20Internal%20Security%20Agency%20has%20confirmed%20that%20attackers%20reached%20the%20industrial%20control%20systems%20of%20five%20water%20treatment%20plants%20during%202025%2C%20in%20some%20cases%20gaining%20the%20ability%20to%20alter%20equipment%20settings.%20The%20target%20is%20no%20longer%20data%20alone%2C%20it%20is%20physical%20process%20control.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fpoland-water-plants-ics-breach-2026)

![Night view of a water treatment plant control room with industrial control system screens and clarifier tanks outside](/__l5e/assets-v1/c7e26eeb-fc3c-41ea-9ffe-2a71e5b07ee5/poland-water-plants-ics-breach-2026-2x.jpg)

Night view of a water treatment plant control room with industrial control system screens and clarifier tanks outside

Why it matters

## What this means for organisations holding critical data

Poland's Internal Security Agency has confirmed that attackers reached the industrial control systems of five water treatment plants during 2025, in some cases gaining the ability to alter equipment settings. The target is no longer data alone, it is physical process control.

In this analysis

1.  01 [What Happened](#section-0)
2.  02 [Why This Matters Beyond Poland](#section-1)
3.  03 [The Firevault View](#section-2)
4.  04 [What Operators Should Do Now](#section-3)

**On this page**[What Happened](#section-0)[Why This Matters Beyond Poland](#section-1)[The Firevault View](#section-2)[What Operators Should Do Now](#section-3)

**Poland's Internal Security Agency (ABW) has confirmed that attackers reached the industrial control systems of five municipal water treatment plants during 2025.** In some cases the intruders gained the ability to change equipment settings, which in the worst case could have affected water supply and water safety. The findings were published in the agency's 2024 to 2025 activity report and were [reported by SecurityWeek](https://www.securityweek.com/polish-security-agency-reports-ics-breaches-at-five-water-treatment-plants/) and [TechCrunch](https://techcrunch.com/2026/05/08/poland-says-hackers-breached-water-treatment-plants-and-the-u-s-is-facing-the-same-threat/) on 8 May 2026.

## What Happened

The ABW named water treatment stations in Jablonna Lacka, Szczytno, Maldyty, Tolkmicko and Sierakowo as targets. According to the agency, attackers gaining access in some cases to industrial control systems held the capability to interfere with the operation of the plants. Reporting attributes the wider campaign to Russia linked hybrid operations, and places it within a sustained escalation across 2024 and 2025.

A Polish official disclosed in August 2025 that a cyber attack could have caused a city to lose its water supply, and that the attack was stopped. The 2026 report gives that warning its detail. It also confirms a shift the security community has been describing for several years: state linked activity against critical national infrastructure is moving from espionage and data theft towards attempts to cause physical disruption.

## Why This Matters Beyond Poland

Water utilities run operational technology. A single set of credentials can map to pumps, valves, chemical dosing, filtration stages, alarms and supervisory screens. The consequence of a breach is not a data subject notification, it is a process that behaves in a way the operator did not command.

The same architecture is present across the United Kingdom in water, energy, transport and local government. Remote access for maintenance, engineering laptops that move between networks, and flat routes between corporate systems and plant systems are all common. Where those routes exist, an intrusion in the office estate is a route into the process estate.

## The Firevault View

Two things need to survive an intrusion of this kind. The first is the ability to trust the configuration: the programmable logic controller programs, set points, engineering baselines, network diagrams and system images that define how a plant is meant to run. The second is the ability to restore that configuration without depending on the compromised environment to supply it.

[Offline Secure Storage](/offline-secure-storage)® addresses both. A gold copy of the engineering and configuration record is held on hardware that is physically disconnected when it is not in use. An attacker inside the connected estate cannot read, encrypt, alter or delete a copy that is not connected. Recovery starts from a verified reference rather than from an assumption that the online backup was untouched.

Where operators are aligning to the NCSC Cyber Assessment Framework, this is an outcome level control rather than a product claim. It supports asset and configuration management under Objective A, protection of essential functions under Objective B, and restoration of essential function under Objective D.

## What Operators Should Do Now

-   Identify the configuration record that a plant cannot run without, and confirm where the authoritative copy is held.
-   Establish an offline gold copy of that record, physically disconnected between authorised access windows.
-   Test restoration of set points and controller programs from the offline copy, on the assumption that the connected estate is untrusted.
-   Review every remote access route into the process environment, including supplier and maintenance access.
-   Record the control against the CAF outcomes the organisation is measured on, rather than treating it as a backup line item.

Poland has provided one of the clearest documented cases in Europe of state linked access to water sector control systems. The lesson for operators elsewhere is not that an attack is coming. It is that the record which allows a plant to be brought back under command must sit somewhere an attacker cannot reach.

_Mark Fermor, Firevault_

## Sources

-   [SecurityWeek, Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants, 8 May 2026](https://www.securityweek.com/polish-security-agency-reports-ics-breaches-at-five-water-treatment-plants/)
-   [TechCrunch, Poland says hackers breached water treatment plants, 8 May 2026](https://techcrunch.com/2026/05/08/poland-says-hackers-breached-water-treatment-plants-and-the-u-s-is-facing-the-same-threat/)
-   [WaterISAC, Poland Warns of Escalating Cyber Threats to Water Utilities and ICS Operations, 21 May 2026](https://www.waterisac.org/tlpclear-poland-warns-of-escalating-cyber-threats-to-water-utilities-and-ics-operations)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)[

![Quinn Emanuel and McDermott breached as law firms become the soft route to client data](/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg)

Breach Analysis 

### Quinn Emanuel and McDermott breached as law firms become the soft route to client data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

8 Sept 2026 4 min 







](/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026)[

![Mathspace breach exposes more than one million students, staff and parents](/images/news/mathspace-data-breach-one-million-students-2026.jpg)

Breach Analysis 

### Mathspace breach exposes more than one million students, staff and parents

An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.

8 Sept 2026 4 min 







](/news/mathspace-data-breach-one-million-students-2026)[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)